Cybersecurity Policy Report, Business Groups Call for ‘Whole-of-Nation’ Response to Cyber Risks From AI, (May 15, 2026)
The Trump administration should respond to recent advances in the ability of AI (artificial intelligence) models to exploit software vulnerabilities with a “whole-of-nation” approach that includes the reestablishment of public-private partnerships that have been eliminated at the Department of Homeland Security, according to 10 trade groups representing the technology, financial, and health care sectors.
“Highly capable AI systems are accelerating vulnerability discovery, lowering the time and resources required to identify exploitable weaknesses, and increasing pressure on existing labor-intensive patching, incident response, disclosure, and risk management processes,” the groups said yesterday in a letter to the administration.
“Recent testing by cybersecurity companies confirms that frontier AI models can accomplish in weeks what previously required a full year of manual penetration testing, and adversaries can now weaponize new vulnerabilities within minutes of disclosure,” they noted.
“Concerningly, these or similar systems will be available to adversary nations who might target the U.S. Government or private sector. The result is a rapidly changing threat environment in which longstanding assumptions, particularly about the speed of attack cycles, the scale of vulnerability discovery, and the integrity of the software supply chain no longer hold,” they said.
“We believe this moment requires a whole-of-nation response commensurate with the size and scale of the challenge,” they added.
They recommended, among other things, that the administration reestablish “cross-sector public-private coordination to help facilitate AI cyber readiness and response.”
“The administration should expand public-private collaboration, and specifically, the Administration should leverage and modernize the Critical Infrastructure Partnership Advisory Council (CIPAC) framework to ensure regular engagement among departments and agencies, sector risk management agencies (SRMAs), critical infrastructure owners and operators, technology providers, cybersecurity firms, and relevant trade associations,” the groups said.
CIPAC and other public-private collaborations were disbanded by DHS last year (CPR, March 13, 2025).
The groups also called for the administration to “prioritize reauthorizing the Cybersecurity Information Sharing Act of 2015,” which gives private-sector entities legal protections when they communicate with each other about cyber threats.
Another recommendation calls on the federal government to strengthen programs that catalog newly discovered cybersecurity vulnerabilities, known as common vulnerabilities and exposures (CVE), given the expected wave of new AI-discovered vulnerabilities.
“The Administration should invest in the CVE ecosystem so it can operate effectively in a global environment and meet AI-accelerated vulnerability discovery and exploitation, as well as the increase in volume,” the groups said.
The letter’s signatories included the Business Software Alliance, Cybersecurity Coalition, Cyber Threat Alliance, and TechNet.
News: FederalLegislation DataSecurity AINews